Can You Sue a DeFi Protocol After a Hack? What the KelpDAO v. LayerZero Case Actually Tests
KelpDAO sued cross-chain infrastructure provider LayerZero on September 25, 2026 over April's $292 million rsETH bridge exploit, alleging negligence and misrepresentation. Here's what that case and two earlier ones — Sarcuni v. bZx DAO and Risley v. Uniswap Labs — actually say about whether a DeFi hack victim has any real legal recourse.
On April 18, 2026, attackers linked to North Korea’s Lazarus Group compromised the off-chain infrastructure behind Kelp DAO’s cross-chain bridge and forged a message claiming 116,500 rsETH had been locked on the source chain when nothing of the sort had happened. No smart contract was exploited — every contract did exactly what it was written to do. The forged message alone was enough to drain roughly $292 million, according to CoinDesk’s reporting at the time — the largest DeFi exploit of 2026.
Five months later, on September 25, 2026, the dispute over who’s responsible reached a courtroom. Evercrest Technologies, the company behind Kelp DAO, filed a civil claim in the Supreme Court of British Columbia against LayerZero Labs and co-founder Bryan Pellegrino, alleging negligence, negligent misrepresentation, and defamation, according to The Block. The claim: LayerZero personnel reviewed and endorsed the exact bridge configuration later blamed for the hack, then publicly pinned the failure entirely on Kelp after the fact. LayerZero disputes this and says it recommended a different, more redundant setup; Pellegrino called the suit meritless and says he’ll defend it in court, per CoinDesk.
If you’ve ever lost money in a DeFi hack and wondered whether you had any real recourse beyond hoping the protocol voluntarily reimburses you, this case is worth watching — not because it will resolve that question, but because it’s testing the exact legal theory most victims eventually ask about: can you actually sue someone when the “someone” is a piece of infrastructure, a DAO, or a handful of pseudonymous developers, rather than a company that clearly owes you money?
The honest answer: usually not, but “usually” is doing real work
Legal recourse against a DeFi protocol after a hack exists on a spectrum, and where a given case falls on it depends on two questions: was there an identifiable person or company who made a specific claim or representation you relied on, and how centralized was the actual decision-making behind the thing that failed? Two prior cases mark the opposite ends of that spectrum, and KelpDAO’s claim sits somewhere in between.
Sarcuni v. bZx DAO — decentralization isn’t automatically a liability shield. In 2021, a bZx developer was phished and roughly $55 million was drained. Victims sued bZx DAO and its governance token holders directly for negligence, arguing that because the DAO had never formally incorporated, it functioned as an unincorporated general partnership under California law — meaning individual token holders could be personally, jointly and severally liable for the DAO’s failures. A federal court agreed the argument was plausible enough to survive a motion to dismiss in 2023, a genuinely novel ruling that alarmed DAO participants industry-wide. The case settled before trial, per Bloomberg Law’s reporting, so the theory was never tested to a final verdict — but it established that “we’re a DAO, not a company” is an argument you have to win, not an assumption courts will grant you for free.
Risley v. Uniswap Labs — neutral infrastructure is a different story. Investors who lost money buying fraudulent “scam tokens” through Uniswap’s interface sued Uniswap Labs, arguing the company should be liable for facilitating the fraud. The Second Circuit Court of Appeals affirmed in February 2025 that a company which writes and deploys permissionless smart contract code isn’t liable under securities law for how third parties later misuse that code — the court found it “defies logic” to hold a smart contract’s drafter responsible for a scammer’s independent decision to launch a fraudulent token on top of it. The remaining state-law claims were dismissed with prejudice in March 2026, per reporting from the DeFi Education Fund, closing out a nearly four-year case with a clean win for the protocol.
The difference between those two outcomes isn’t decentralization versus centralization in the abstract — it’s whether the defendant did something specific and identifiable that a plaintiff can point to. bZx DAO’s token holders were arguably making real governance decisions about a protocol with a known security posture. Uniswap Labs built infrastructure that anyone could use for anything, including fraud it had no hand in and no way to prevent.
Where KelpDAO’s claim against LayerZero actually fits
This is what makes the new lawsuit worth following: it isn’t a “your code enabled someone else’s fraud” claim like Risley, and it isn’t purely a “you failed to secure your own system” claim like Sarcuni. KelpDAO alleges LayerZero, as a company with named executives, affirmatively reviewed a specific configuration — a “1-of-1” verifier setup for validating cross-chain messages — and told Kelp it was acceptable, only to blame that same setup publicly after it was exploited. If true, that’s closer to a claim of negligent misrepresentation (a false or careless statement someone relied on to their detriment) than a claim about the mere existence of open infrastructure. LayerZero’s defense, notably, isn’t “we’re not liable for how our tools get used” — it’s a factual dispute over what was actually recommended, with LayerZero maintaining it advised using multiple independent verifiers specifically to avoid the single point of failure that was exploited. CoinDesk previously reported that data on active LayerZero deployments showed roughly 47% of them used the same single-verifier setup at the time of the hack — a detail that will likely matter to whether a court finds LayerZero’s endorsement, if proven, was an isolated miscommunication or a known, tolerated risk across the ecosystem.
None of this means KelpDAO wins. Negligent misrepresentation claims require proving a specific statement was made, that it was false or careless, and that the plaintiff reasonably relied on it — a higher bar than simply showing something went wrong. But it’s a meaningfully different theory than either prior case, which is exactly why it’s a useful one to watch rather than a settled precedent to rely on.
| Sarcuni v. bZx DAO | Risley v. Uniswap Labs | KelpDAO v. LayerZero | |
|---|---|---|---|
| Loss | $55M (2021 phishing/hack) | Losses on fraudulent third-party tokens | $292M (April 2026 bridge exploit) |
| Defendant | DAO token holders, as alleged general partnership | Uniswap Labs & founders | LayerZero Labs & co-founder |
| Core theory | Negligence — DAO failed to secure the protocol it governed | Securities/state law — platform facilitated third-party fraud | Negligence & negligent misrepresentation — endorsed a specific unsafe config |
| Key ruling | Survived motion to dismiss (2023); DAO could be a “general partnership” | 2nd Cir.: code drafters not liable for third-party misuse (2025); dismissed w/ prejudice (2026) | Pending — filed Sept. 25, 2026 |
| Status | Settled before trial | Fully resolved, in the platform’s favor | Ongoing; LayerZero calls it meritless |
What this actually means if you’re sitting on a DeFi hack loss
A lawsuit is not your recovery plan by default. Even the strongest of these cases took years and, in Sarcuni’s case, ended in a private settlement rather than a public verdict establishing clear rules going forward. If you’re holding a loss from a bridge exploit, an oracle failure, or a protocol hack, plan your finances around the loss being real and permanent, the way you would after a wrapped-token peg break — and treat any later recovery, from litigation or a protocol’s own restitution fund, as a bonus, not a plan.
What determines whether a claim is even worth investigating is specificity, not sympathy. “The protocol got hacked and I lost money” is not, on its own, a viable negligence claim against anyone — hacks happen to well-run protocols too. What matters is whether an identifiable company or person made a specific, checkable claim (an audit, a security endorsement, a “your funds are safe” statement) that turned out to be false or reckless, and whether you can show you relied on it. Save every public statement, audit report, and marketing claim a protocol made before you lost money — not because you’re planning to sue, but because that documentation is what turns a generic complaint into an actual legal claim if a class action later forms.
Individual litigation rarely pencils out; class actions and DAO-level claims sometimes do. Every case above involved either an enormous single loss or a pooled group of plaintiffs. If you lost a smaller amount, your realistic path is watching whether other affected users or the protocol itself organizes a collective claim, and joining it — not retaining your own securities litigator over a five-figure loss.
A hack loss and a scam loss are not the same claim, tax-wise or legally. How you frame what happened to you — a protocol failure versus theft versus an ordinary market loss — changes both your tax treatment and any legal options. See Can You Claim a Tax Loss on Crypto You Can’t Sell? for how the tax side of an unrecoverable DeFi position actually works, since a pending lawsuit against a third party doesn’t itself change how or when you can claim the loss on your own return.
The KelpDAO case won’t resolve the broader question of DeFi liability — it’s one company’s claim about one specific set of facts, and LayerZero disputes most of them. But it’s a live test of the theory that sits between “decentralized code has no owner” and “someone made a specific promise and broke it,” and how it comes out will tell you something real about where courts are willing to draw that line the next time a bridge, an oracle, or a “trusted” piece of infrastructure fails and takes your money with it.
FAQ
If I held rsETH or was otherwise affected by the KelpDAO exploit, does this lawsuit get my money back? Not directly, and not soon. The lawsuit was filed by Evercrest Technologies, the company behind KelpDAO, against LayerZero — it’s one protocol suing another over who bears responsibility for the exploit, not a class action on behalf of individual rsETH holders. Even if KelpDAO wins, any recovery would go to KelpDAO’s treasury, not automatically to individual users, and a civil suit in the Supreme Court of British Columbia is realistically a multi-year process before any money moves. If you were affected, look to KelpDAO’s own compensation or restitution plan for the protocol itself, not this lawsuit, as your nearer-term source of information.
Does a protocol being “decentralized” protect its developers from being sued? Not automatically, and Sarcuni v. bZx DAO is the clearest example why. A California court ruled in 2023 that a DAO without a formal legal structure could be treated as a general partnership under state law, meaning individual token holders could potentially be held jointly and severally liable for the DAO’s negligence. That ruling survived a motion to dismiss and pushed the case to a settlement before any trial verdict — but it showed that calling something a DAO doesn’t automatically create a liability shield the way incorporating a company does.
Is filing a lawsuit like this realistic for an ordinary investor with a five- or six-figure loss, not a quarter-billion-dollar one? Rarely, on your own. Civil litigation — discovery, expert witnesses, years of proceedings — costs far more than most individual crypto losses, which is why the cases that actually get filed tend to involve either a large single loss, a class of many plaintiffs pooling costs, or a defendant with deep pockets worth pursuing. For most people, the realistic path is documenting the loss thoroughly and watching for a class action to join, not filing individually.
Does the Uniswap ruling mean no DeFi lawsuit over a hack or loss can ever succeed? No — it resolved a specific fact pattern, not the whole category. Risley v. Uniswap Labs was about users who lost money buying fraudulent tokens through Uniswap’s interface, and the courts held that a company providing permissionless, unowned smart contract infrastructure isn’t liable for how third parties misuse it. KelpDAO’s claim is different: it alleges LayerZero itself reviewed and endorsed a specific security configuration — an affirmative representation, not just neutral infrastructure. Which theory applies depends entirely on the specific facts of each case.